Hush Line Fixes Security Issue in Whistleblower Management System
CVE-2024-55888
7.1HIGH
What is CVE-2024-55888?
Hush Line, an open-source whistleblower management system, has a vulnerability due to a misconfigured production server that fails to implement a content security policy or necessary security headers. This flaw, present in versions 0.1.0 to 0.3.4, potentially enables attackers to bypass cross-site scripting (XSS) filters, which could compromise the security of user data and the application. The vulnerability has been addressed in version 0.3.5, which includes critical security updates.
Affected Version(s)
hushline >= 0.1.0, < 0.3.5